A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ly Corporation
Ly Corporation central Dogma |
|
| Vendors & Products |
Ly Corporation
Ly Corporation central Dogma |
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | LDAP Injection in SearchFirstActiveDirectoryRealm Allows Directory Enumeration | |
| Weaknesses | CWE-90 |
Mon, 22 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: LY-Corporation
Published: 2026-06-22T02:37:35.370Z
Updated: 2026-06-22T16:12:07.208Z
Reserved: 2026-06-09T06:50:03.618Z
Link: CVE-2026-11748
Updated: 2026-06-22T16:11:30.982Z
No data.
No data.